URLhaus Database

You are currently viewing the URLhaus database entry for https://protestlabsmovings.es/domry/LIjJHBNFy.exe which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:405789
URL: https://protestlabsmovings.es/domry/LIjJHBNFy.exe
URL Status:Offline
Host: protestlabsmovings.es
Date added:2020-06-30 20:19:32 UTC
Last online:2020-07-02 02:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Status unknown
AdGuard :Blocked
Cloudflare :Blocked
dns0.eu :Status unknown
ProtonDNS :Status unknown
OpenBLD :Blocked
DNS4EU :Blocked
Reporter: abuse_ch
Abuse complaint sent (?): Yes (2020-06-30 20:20:03 UTC to abusenoc{at}layerhost[dot]com)
Takedown time:1 day, 6 hours, 12 minutes Poor (down since 2020-07-02 02:32:39 UTC)
Tags:exe Loki link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-07-02n/aexe 7afb56dd48565c3c9804f683c80ef47e5333f847f2d3211ec11ed13ad36061e1Virustotal results 0.00% 
2020-07-02n/aexe 55388e13d65ddcd067ba248d76628b6ebbdb1a51fbcef36589d11604fb3a0e54n/aLoki
2020-07-01n/aexe 1df4c75f2c8119a401b59d5954a031c0af8490764a7127dcd02185b27154162cn/aLoki
2020-07-01n/aexe 1feb6a5f318bf4076cd084cd271d697491cb897e1ab91d397d7f08f66d2e1799n/a Loki
2020-07-01n/aexe 1f39849a2b65f4a84501e900aa8226f4ab93f89a51203640a77c6c33cb470589n/aLoki
2020-07-01n/aexe 69f1c09a3db83dae38ff8fb5f323689ac245b2bde06133d49d33d1e05ada8b7fn/aLoki
2020-07-01n/aexe e4aa32ccbd12c96a8f49039a2e2e7395089a0cb9a524ba38dc33f8066275482cn/aLoki
2020-07-01n/aexe d1a78264bce1e629719b047552173eb7b6a4805b2cf1d92de0231d7762dbc224n/aLoki
2020-07-01n/aexe 551d0cab361858a7aabce4f156aba860a3e40a4a17962a0b5b822402b37b4305n/aLoki
2020-07-01n/aexe f1ff4a8c0b69b04ac52186300cc66f5c122ab87ff70d757211ccc049013299e4n/aLoki
2020-07-01n/aexe 2c249db68985414c6d06f92cc5b113657fe7f3b6f647a7119147bd8fbbf95f82n/aLoki
2020-07-01n/aexe 950afdfc712687ef06676b890a73936fecf980e947f9f2f0d36ea89dc6b3f40cn/aLoki
2020-06-30n/aexe ff9ebbc66b229b2170d67b4475d64d0eba2a6c01ff8ad155299985d32149e2e1n/aLoki
2020-06-30n/aexe 31b2092367fc66eddbde56095bed49cc271d7a6e388b1f70951bd27cc4fa3c9aVirustotal results 20.83% Loki
2020-06-30n/aexe 06384ff303fadeb1b7f8a3eb85b996cdb4e738f30397e927da65204649056e8dn/aLoki